• [^] # Re: Pas mieux ...

    Posté par . En réponse au message Iptables et restrictions horaires. Évalué à 1.

    Bonjour,

    Voilà ce que ça donne:

    iptables -vL
    Chain INPUT (policy DROP 1067K packets, 265M bytes)
    pkts bytes target prot opt in out source destination
    719M 767G SuiviCnx 0 -- any any anywhere anywhere
    1075K 62M ACCEPT tcp -- any any anywhere anywhere tcp dpt:www
    414 22076 ACCEPT tcp -- any any anywhere anywhere tcp dpt:https
    112K 5444K ACCEPT tcp -- any any anywhere anywhere tcp dpt:smtp
    445K 26M ACCEPT tcp -- any any anywhere anywhere tcp dpt:ssh
    1108 46448 ACCEPT tcp -- any any anywhere anywhere tcp dpt:domain
    108K 7016K ACCEPT udp -- any any anywhere anywhere udp dpt:domain
    0 0 ACCEPT icmp -- any any anywhere anywhere icmp echo-reply
    0 0 ACCEPT icmp -- any any anywhere anywhere icmp destination-unreachable
    0 0 ACCEPT icmp -- any any anywhere anywhere icmp redirect
    17092 1109K ACCEPT icmp -- any any anywhere anywhere icmp echo-request
    0 0 ACCEPT icmp -- any any anywhere anywhere icmp time-exceeded
    134K 8002K ACCEPT tcp -- any any anywhere anywhere tcp dpt:ftp
    9 428 ACCEPT tcp -- any any anywhere anywhere tcp dpt:ftp-data
    175 11546 ACCEPT tcp -- any any anywhere anywhere tcp dpts:60000:60500 state NEW,RELATED,ESTABLISHED
    0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:4661
    0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:4662
    0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:4665
    339 17664 ACCEPT tcp -- any any anywhere anywhere tcp spt:4661
    406 24852 ACCEPT tcp -- any any anywhere anywhere tcp spt:4662
    251 14556 ACCEPT udp -- any any anywhere anywhere udp spt:4665
    246 51168 ACCEPT udp -- any any anywhere anywhere udp dpt:8767
    498K 29M DROP tcp -- any any anywhere anywhere tcp dpt:loc-srv
    32 4978 DROP udp -- any any anywhere anywhere udp dpt:loc-srv
    24 1152 DROP tcp -- any any anywhere anywhere tcp dpt:netbios-ns
    9248 721K DROP udp -- any any anywhere anywhere udp dpt:netbios-ns
    13 616 DROP tcp -- any any anywhere anywhere tcp dpt:netbios-dgm
    1 32 DROP udp -- any any anywhere anywhere udp dpt:netbios-dgm
    99846 5975K DROP tcp -- any any anywhere anywhere tcp dpt:netbios-ssn
    0 0 DROP udp -- any any anywhere anywhere udp dpt:netbios-ssn
    362K 19M DROP tcp -- any any anywhere anywhere tcp dpt:microsoft-ds
    0 0 DROP udp -- any any anywhere anywhere udp dpt:microsoft-ds
    508K 46M LOG 0 -- any any anywhere anywhere limit: avg 1/sec burst 5 LOG level warning prefix `Packet log:'

    Chain FORWARD (policy DROP 0 packets, 0 bytes)
    pkts bytes target prot opt in out source destination
    0 0 DROP 0 -- any any pc1.maison.home anywhere
    0 0 DROP 0 -- any any pc2.maison.home anywhere
    857M 480G SuiviCnx 0 -- any any anywhere anywhere
    17 6568 ACCEPT tcp -- eth1 eth0 anywhere phil-linux.maison.home tcp dpt:4661
    230K 12M ACCEPT tcp -- eth1 eth0 anywhere phil-linux.maison.home tcp dpt:4662
    10344 978K ACCEPT udp -- eth1 eth0 anywhere phil-linux.maison.home udp dpt:4665

    Chain OUTPUT (policy ACCEPT 534M packets, 154G bytes)
    pkts bytes target prot opt in out source destination

    Chain SuiviCnx (2 references)
    pkts bytes target prot opt in out source destination
    8360K 571M ACCEPT 0 -- !eth1 any anywhere anywhere state NEW
    1564M 1246G ACCEPT 0 -- any any anywhere anywhere state RELATED,ESTABLISHED


    iptables -t nat -vL
    Chain PREROUTING (policy ACCEPT 9120K packets, 721M bytes)
    pkts bytes target prot opt in out source destination
    0 0 LOG 0 -- any any anywhere anywhere state INVALID limit: avg 1/sec burst 5 LOG level warning prefix `Invalid Packet (NAT):'
    0 0 DROP 0 -- any any anywhere anywhere state INVALID
    7 4628 DNAT tcp -- eth1 any anywhere anywhere tcp dpt:4661 to:192.168.0.60:4661
    230K 12M DNAT tcp -- eth1 any anywhere anywhere tcp dpt:4662 to:192.168.0.60:4662
    548 63858 DNAT udp -- eth1 any anywhere anywhere udp dpt:4665 to:192.168.0.60:4665

    Chain POSTROUTING (policy ACCEPT 2060K packets, 142M bytes)
    pkts bytes target prot opt in out source destination
    6858K 465M MASQUERADE 0 -- any eth1 anywhere anywhere

    Chain OUTPUT (policy ACCEPT 4163K packets, 363M bytes)
    pkts bytes target prot opt in out source destination


    iptables -t mangle -vL
    Chain PREROUTING (policy ACCEPT 1576M packets, 1247G bytes)
    pkts bytes target prot opt in out source destination
    1003K 47M LOG 0 -- any any anywhere anywhere state INVALID limit: avg 1/sec burst 5 LOG level warning prefix `Invalid Packet (MANGLE):'
    1227K 57M DROP 0 -- any any anywhere anywhere state INVALID
    11704 4990K TOS tcp -- any any anywhere anywhere tcp spt:ssh TOS set Minimize-Delay

    Chain INPUT (policy ACCEPT 719M packets, 767G bytes)
    pkts bytes target prot opt in out source destination

    Chain FORWARD (policy ACCEPT 857M packets, 480G bytes)
    pkts bytes target prot opt in out source destination

    Chain OUTPUT (policy ACCEPT 534M packets, 154G bytes)
    pkts bytes target prot opt in out source destination

    Chain POSTROUTING (policy ACCEPT 1392M packets, 634G bytes)
    pkts bytes target prot opt in out source destination


    'maison.home' est mon domaine local (géré par bind), pc1 et pc2 sont les 2 pc en question.